Skip to content

[oss] Fix blob presigned URL validation when fs.oss.sld.enabled is set - #10230

Merged
JingsongLi merged 2 commits into
apache:masterfrom
thswlsqls:fix/oss-presigned-url-sld
Oct 3, 2026
Merged

JingsongLi merged 2 commits into
apache:masterfrom
thswlsqls:fix/oss-presigned-url-sld

Conversation

@thswlsqls

Copy link
Copy Markdown
Contributor

Purpose

fix #10229

  • With fs.oss.sld.enabled=true the shared OSS client signs path-style URLs (host = endpoint, path = /bucket/key), but OSSBlobPresigner.validatePresignedUrl always expected bucket.<endpoint> and /key, so every request failed with "invalid target" (public, internal and PrivateLink endpoints).
  • When the client configuration has SLD enabled, expect the endpoint host and /bucket/key; bucket, key and HTTPS are still checked. The SLD-off path is unchanged.
  • CNAME custom domains are still rejected (out of scope). The Python presigner has the same host assumption but no SLD option today.

Tests

  • Added three OSSFileIOTest cases: path-style URLs on public/internal/PrivateLink endpoints (plus wrong-bucket rejection), and SDK-signed URLs for an encoded key and an endpoint port. All three fail without the fix.
  • Stubbed getClientConfiguration() in 4 existing mock setups (no assertion changes).
  • mvn -pl paimon-filesystems/paimon-oss-impl clean install (JDK 11) passed: OSSFileIOTest 20/20, checkstyle and spotless green.

With fs.oss.sld.enabled the shared OSS client signs path-style URLs
(host = endpoint host, path = /bucket/key), but validatePresignedUrl
always expected a virtual-hosted URL, so every presigned URL request was
rejected as an invalid target. Expect the path-style shape when the
client configuration has SLD enabled; the default path is unchanged and
HTTPS is still required.

Generated-by: Claude Code
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@JingsongLi

Copy link
Copy Markdown
Contributor

Requirement fit: SUPPORTED. Implementation: FINDINGS at c60393a1c4.

[P2] Update the downstream Jindo presigning fixture for the new configuration access

OSSBlobPresigner.java:224 now calls client.getClientConfiguration().isSLDEnabled(). The existing JindoFileIOTest#testCreateBlobPresignedUrlUsesOssClient also reaches this implementation, but its Mockito OSSClient leaves that method unstubbed, returning null. The test now throws an IOException caused by a NullPointerException at this new line. This is the actual failure in both the JDK 8 and JDK 11 Core/integrations CI jobs.

I reproduced the failing Jindo method locally with normal Maven checks. Running the same method with only the presigner implementation restored to the base passes. Please add a getClientConfiguration() stub returning new ClientConfiguration() to the Jindo fixture, as this PR already does for the OSS fixtures, and rerun the affected CI. This is a test/build regression; real SDK clients have a non-null configuration.

The SLD addressing fix has end-to-end value, and its SDK/security contract looks correct. The full OSSFileIOTest suite passes all 20 tests locally on both JDK 8 and JDK 11, including actual SDK-signed encoded-key/port URLs and bucket rejection. Production validation still needs the affected integration checks to pass.

OSSBlobPresigner.validatePresignedUrl now reads
getClientConfiguration().isSLDEnabled(). JindoFileIOTest exercises the
same presigner through JindoBlobPresigner, and its Mockito OSSClient left
getClientConfiguration() unstubbed, so the call hit a null and failed
testCreateBlobPresignedUrlUsesOssClient. Stub it with a default
ClientConfiguration, as the OSS fixtures already do.

Generated-by: Claude Code
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@thswlsqls

Copy link
Copy Markdown
Contributor Author

@JingsongLi Thanks for tracking this down. Fixed — JindoFileIOTest#testCreateBlobPresignedUrlUsesOssClient now stubs getClientConfiguration() with new ClientConfiguration(), matching the OSS fixtures.

On the new head, Core/integrations JDK 11 is green. On JDK 8, JindoFileIOTest (5/5) and OSSFileIOTest (20/20) passed, but the job later failed because the hosted runner lost communication.

Could you rerun the JDK 8 job when you have a chance?

@JingsongLi

Copy link
Copy Markdown
Contributor

+1

@JingsongLi
JingsongLi merged commit e396992 into apache:master Oct 3, 2026
33 of 36 checks passed
@thswlsqls
thswlsqls deleted the fix/oss-presigned-url-sld branch October 4, 2026 03:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] OSS blob presigned URL is always rejected when fs.oss.sld.enabled is set

2 participants